Tag

#Plugin Vulnerability

newsHIGH 8.1

Unauthenticated Remote Code Execution Vulnerability in ProfilePress WordPress Plugin

The ProfilePress WordPress plugin before version 4.17.2 is vulnerable to unauthenticated remote code execution. This vulnerability allows attackers to install and activate arbitrary plugins, potentially leading to PHP code execution as the web-server user. The vulnerability has a CVSS score of 8.1, indicating high severity.

1 source
blogHIGH 8.1

Understanding and Defending Against CVE-2026-19718: Weak Secret Generation in WordPress Plugins

CVE-2026-19718 is a high-severity vulnerability affecting several WordPress plugins, including BlogVault Backup & Staging, MalCare WordPress Security Plugin, and The WP Remote WordPress Plugin. The vulnerability allows unauthenticated attackers to obtain data derived from a secret binding a site to its remote management service, which is generated using a weak pseudo-random number generator. This enables attackers to recover the secret and gain administrative access to the site. The vulnerability has a CVSS score of 8.1 and is considered high severity.

1 source
articleHIGH 8.8

CVE-2026-15001: Privilege Escalation in bLoyal: Loyalty & Promotions by bLoyal WordPress Plugin

The bLoyal: Loyalty & Promotions by bLoyal WordPress plugin is vulnerable to Privilege Escalation (CVE-2026-15001, CVSS 8.8) in all versions up to 3.1.611.78. Authenticated attackers with Subscriber-level access can exploit this vulnerability to escalate privileges to Administrator, potentially leading to full site compromise. Immediate patching is recommended.

1 source
newsHIGH 8.2

CVE-2026-14829: Unauthenticated License Deactivation in Checkimate WordPress Plugin

The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 has a vulnerability allowing unauthenticated attackers to deactivate the plugin's premium licensing state and erase the stored license key. This vulnerability has a CVSS score of 8.2, indicating high severity. Affected users should update to a patched version.

1 source